Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SQL Injection #49

Open
MSWS opened this issue Apr 27, 2021 · 1 comment
Open

SQL Injection #49

MSWS opened this issue Apr 27, 2021 · 1 comment

Comments

@MSWS
Copy link

MSWS commented Apr 27, 2021

It is possible for players to SQL Inject by changing their gang name. The name is not properly escaped in the code, so for example " or "" would break a large portion of the database.

@Headline
Copy link
Owner

Thanks! A pretty serious reason to avoid using this plugin entirely until a fork is properly maintained

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants